{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_5r4aw6tfj9m7","handle":"iflow-mcp-threat-zone-threatzonemcp","url":"https://wellknown.network/agents/iflow-mcp-threat-zone-threatzonemcp","links":{"self":"https://wellknown.network/agents/iflow-mcp-threat-zone-threatzonemcp/record.json","html":"https://wellknown.network/agents/iflow-mcp-threat-zone-threatzonemcp","markdown":"https://wellknown.network/agents/iflow-mcp-threat-zone-threatzonemcp/record.md","api":"https://wellknown.network/api/v1/agents/iflow-mcp-threat-zone-threatzonemcp","status":"https://wellknown.network/api/v1/agents/iflow-mcp-threat-zone-threatzonemcp/status","claim":"https://wellknown.network/agents/iflow-mcp-threat-zone-threatzonemcp/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/iflow-mcp-threat-zone-threatzonemcp/claim.json","badge":"https://wellknown.network/agents/iflow-mcp-threat-zone-threatzonemcp/badge.svg","openapi":"https://wellknown.network/openapi.json","history":"https://wellknown.network/api/v1/agents/iflow-mcp-threat-zone-threatzonemcp/history","tools":"https://wellknown.network/api/v1/agents/iflow-mcp-threat-zone-threatzonemcp/tools"},"ard":{"identifier":"urn:air::server:iflow-mcp-threat-zone-threatzonemcp","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"iflow-mcp_threat-zone_threatzonemcp","summary":"Model Context Protocol (MCP) server for Threat.Zone API","description":"```\n████████╗██╗  ██╗██████╗ ███████╗ █████╗ ████████╗   ███████╗ ██████╗ ███╗   ██╗███████╗███╗   ███╗ ██████╗██████╗ \n╚══██╔══╝██║  ██║██╔══██╗██╔════╝██╔══██╗╚══██╔══╝   ╚══███╔╝██╔═══██╗████╗  ██║██╔════╝████╗ ████║██╔════╝██╔══██╗\n   ██║   ███████║██████╔╝█████╗  ███████║   ██║        ███╔╝ ██║   ██║██╔██╗ ██║█████╗  ██╔████╔██║██║     ██████╔╝\n   ██║   ██╔══██║██╔══██╗██╔══╝  ██╔══██║   ██║       ███╔╝  ██║   ██║██║╚██╗██║██╔══╝  ██║╚██╔╝██║██║     ██╔═══╝ \n   ██║   ██║  ██║██║  ██║███████╗██║  ██║   ██║   ██╗███████╗╚██████╔╝██║ ╚████║███████╗██║ ╚═╝ ██║╚██████╗██║     \n   ╚═╝   ╚═╝  ╚═╝╚═╝  ╚═╝╚══════╝╚═╝  ╚═╝   ╚═╝   ╚═╝╚══════╝ ╚═════╝ ╚═╝  ╚═══╝╚══════╝╚═╝     ╚═╝ ╚═════╝╚═╝     \n```\n\n# Threat.Zone MCP Server\n\nA Model Context Protocol (MCP) server for the Threat.Zone API, built with FastMCP. This server provides LLMs with access to Threat.Zone's malware analysis capabilities through standardized MCP tools.\n\n## Features\n\n- **File Analysis**: Submit files for malware analysis including sandbox execution, static analysis, and CDR (Content Disarm and Reconstruction)\n- **URL Analysis**: Analyze URLs for threats and malicious content\n- **Submission Management**: Retrieve detailed analysis results, indicators, IoCs, and YARA rules\n- **Network Analysis**: Access DNS queries, HTTP/TCP/UDP requests, and network threats\n- **Report Generation**: Download sanitized files and HTML reports\n- **User Management**: Get user information and submission limits\n\n## Installation\n\n### Using pip\n\n```bash\npip install threatzone-mcp\n```\n\n### Using uv (recommended)\n\n```bash\nuv add threatzone-mcp\n```\n\n### Development Installation\n\n```bash\ngit clone https://github.com/threat-zone/threatzonemcp.git\ncd threatzonemcp\nuv sync --dev\n```\n\n## Configuration\n\nSet your Threat.Zone API credentials as environment variables:\n\n```bash\nexport THREATZONE_API_KEY=\"your_api_key_here\"\n# Optional: For private tenants or on-premise deployments\nexport THREATZONE_API_URL=\"https://your-tenant.threat.zone\"\n`…","publisher":null,"homepage":"https://threat.zone/docs","repository":"https://github.com/threat-zone/threatzonemcp","version":"0.1.0","license":"GPL-3.0-or-later","protocols":["mcp"],"tags":["mcp","threat-zone","malware","security","analysis"],"pricing":null,"endpoints":[{"url":"pypi:iflow-mcp_threat-zone_threatzonemcp","type":"package_pypi","auth":null,"probeable":false}],"skills":null,"tools":null,"extra":null,"attribution":{"kind":"pypi","name":"pypi","license":"pypi","repoUrl":"pypi","summary":"pypi","version":"pypi","description":"pypi","homepageUrl":"pypi"}},"derived":{"capabilities":[{"slug":"dev.ci-cd","name":"CI/CD & Deploy","confidence":0.779,"provenance":"derived"},{"slug":"dev.version-control","name":"Version Control","confidence":0.745,"provenance":"derived"}],"categories":["dev"],"language":"en"},"observed":{"status":"unknown","statusReason":"Distributed as a package to run locally; no network endpoint to check.","lastOkAt":null,"lastProbedAt":null,"statusComputedAt":null,"reliability30d":null,"latestObservations":[],"tools":null,"package":{"name":"iflow-mcp_threat-zone_threatzonemcp","registry":"pypi","observedAt":"2026-09-15T20:21:29.700Z","publishedAt":"2026-01-29T08:58:52.076529Z","latestVersion":"0.1.0"},"toolSurface":null,"endpointFacts":[]},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"pypi","key":"iflow-mcp_threat-zone_threatzonemcp","url":"https://pypi.org/project/iflow-mcp_threat-zone_threatzonemcp/","firstSeenAt":"2026-09-09T21:24:26.159Z","fetchedAt":"2026-09-15T20:20:09.613Z","normalizedAt":"2026-09-15T20:20:09.613Z"}]},"firstSeenAt":"2026-09-09T21:24:26.159Z","updatedAt":"2026-09-15T20:21:29.700Z"}